Description
Position Overview
SOP Development, Maintenance & Operationalization:
- Draft, review, and continuously refine detailed Standard Operating Procedures (SOPs) that translate complex NIST SP 800-171 controls into step-by-step technical workflows for IT staff.
- Audit operational practices regularly to ensure procedural alignment with active SOPs, updating documentation whenever technical environments or baseline configurations evolve.
- Maintain the centralized repository of GRC SOPs, work instructions, and execution templates, ensuring version control and strict alignment with the enterprise System Security Plan (SSP).
- Partner with System Administrators and IT Operations to convert POA&M remediation outcomes into formalized, repeatable SOPs to prevent recurring compliance gaps.
Daily Control Monitoring & Evidence Analysis
- Perform daily, weekly, and monthly operational reviews of technical controls across all 14 NIST SP 800-171 practice domains (e.g., auditing SIEM logs, validating MFA enforcement, and reviewing access requests) in accordance with established SOPs.
- Collect, inspect, and archive technical artifacts and evidence (configuration baselines, backup logs, patch records) to maintain continuous audit readiness.
- Identify, document, and report control drift or non-compliance issues across hybrid Active Directory, cloud environments (GCC High/Azure), and virtualization platforms.
- Execute recurring internal control tests to verify that technical safeguards operate as documented in the SSP and procedural guidelines.
Risk Tracking & POA&M Execution
- Track and validate the daily progress of remediation items listed on the active Plan of Action & Milestones (POA&M).
- Collaborate directly with System Administrators and IT Operations to test and verify fixed items before closing out open POA&M entries.
- Monitor daily CUI flow paths and enclave access logs to verify that Controlled Unclassified Information (CUI) boundary controls remain strictly enforced.
- Conduct routine vendor risk checks, verifying that subcontractors maintain active compliance with DFARS 252.204-7012 / 7020 flow-down requirements.
Audit Support & Reporting
- Analyze compliance data to support regular SPRS score updates and internal readiness reporting.
- Serve as the primary hands-on evidence and procedural coordinator during internal compliance reviews, DIBCAC audits, and external C3PAO assessments.
- Generate weekly operational risk metrics, process execution logs, and gap analysis reports for the IT Security Manager.
Qualifications & Requirements
- Experience: 2–4+ years of hands-on experience performing IT compliance monitoring, internal auditing, procedural documentation, or security control testing in a DoD/DFARS environment.
- Documentation & SOP Skills: Proven ability to author clear, step-by-step technical Standard Operating Procedures (SOPs), system administration guides, and audit-ready control execution logs.
- Framework Knowledge: Direct experience monitoring and analyzing controls under NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012.
- Technical Familiarity: Practical experience inspecting control evidence within Active Directory / Entra ID, Microsoft 365 / GCC High, firewalls, SIEM platforms, and hypervisors.
- Education: Bachelor’s Degree in Cybersecurity, Information Systems, or equivalent practical technical experience.
Preferred Certifications
- CMMC / Compliance: CCP (CMMC Certified Professional) or CISA.
- General Security: Security+, Network+, or SSCP.